CVE-2024-41928

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.
Configurations

No configuration.

History

No history.

Information

Published : 2024-09-05 04:15

Updated : 2024-11-21 09:33


NVD link : CVE-2024-41928

Mitre link : CVE-2024-41928

CVE.ORG link : CVE-2024-41928


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write

CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input